PT-2023-18886 · Pimcore · Pimcore

Publicado

2023-04-27

·

Atualizado

2023-05-08

·

CVE-2023-2328

CVSS v3.1

5.2

Média

VetorAV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions pimcore/pimcore versions prior to 10.5.21
Description This issue is related to Cross-site Scripting (XSS) - Generic in the GitHub repository pimcore/pimcore. It has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2328
GHSA-2295-VH28-PPHC

Produtos afetados

Pimcore